trim_whitespace in lexer.l in libConfuse v3.2.1 has an out-of-bounds read.
The product reads data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
http://hac425.unaux.com/index.php/archives/64/ | not applicable |
https://lists.debian.org/debian-lts-announce/2018/08/msg00017.html | third party advisory mailing list |
https://github.com/martinh/libconfuse/issues/109 | issue tracking patch exploit third party advisory |